What is CVE-2026-15368?
The User Profile Builder WordPress plugin before version 3.16.4 does not correctly bind automatic login after registration, allowing unauthenticated attackers to obtain an authenticated session for an arbitrary existing user, including administrators. Update the plugin to the latest version to mitigate this issue.
Azərbaycanca: User Profile Builder (3.16.4-dən əvvəl) WordPress pluginində qeydiyyatdan sonra avtomatik login funksiyası yanlış bağlanır. Bu zəiflik autentifikasiya olunmamış hücumçuya istənilən mövcud istifadəçinin (o cümlədən administrator) sessiyasını ələ keçirməyə imkan verir. Plugin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
In which plugin was CVE-2026-15368 discovered and what function does it affect?
The vulnerability was discovered in the User Profile Builder WordPress plugin, specifically affecting the automatic login after registration function. Because this function is incorrectly bound, it allows unauthenticated attackers to obtain an authenticated session for an arbitrary existing user.
How can I mitigate the risk of CVE-2026-15368?
Update the User Profile Builder plugin to the latest version (3.16.4 or higher).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.